FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Governance ┬╖ 5 minute read

AI and SOX Compliance: Internal Controls When AI Touches the Ledger

AI and SOX compliance means treating AI used in financial reporting as part of the internal control environment: documenting where AI contributes to reconciliations, journal entries, and estimates, keeping humans accountable for control decisions, applying change management and access controls to prompts and models, producing evidence auditors can test, maintaining segregation of duties, and including AI in control testing.

By FISTA Solutions┬╖ AI-Native Engineering Team┬╖
AI and SOX Compliance: Internal Controls When AI Touches the Ledger article cover

Finance teams are putting AI into the close: matching transactions, drafting variance explanations, proposing accruals, assembling evidence. Each of these touches financial reporting, which means each becomes part of the internal control environment that management certifies and auditors test. The question is not whether AI is allowed but how it is documented, controlled, evidenced, and tested. This guide covers those requirements, drawing on FISTA Solutions' AI enablement practice. A representative build is in how to build an ai financial close assistant and the audit function's view in ai in audit. This article is general guidance, not legal, accounting, or audit advice; organizations should confirm requirements with their auditors and controls teams.

Where does AI touch financial reporting controls?

ProcessAI contributionControl implication
ReconciliationsMatching, exception identification, explanation draftingMatch logic and thresholds documented; human approval
Journal entriesProposed entries with supportApproval by authorized role; evidence linked
Accruals and estimatesSuggested amounts from historical patternsHuman judgment documented; model inputs evidenced
Variance analysisDrafted explanations from ledger and operational dataReproducibility from data as of close
DisclosuresDrafts from structured dataReview and sign-off; source traceability
Data feedsExtraction and classification of source documentsAccuracy controls; error handling

How should AI's role in controls be documented?

For each control the AI supports: what the AI does, what it does not do, the thresholds and rules it applies, the human decision that follows, the evidence produced, and the owner. This becomes part of the control narrative and the risk and control matrix. AI described as a black box inside a control is a deficiency waiting to be identified. Documentation standards are in what is a model card and record practice in ai record keeping requirements.

How do you keep humans accountable?

AI prepares, proposes, matches, drafts, and attaches evidence; accountable people approve, post, and sign off. Approval gates in the tool layer enforce that AI-proposed entries and reconciliations are approved by authorized roles, with the decision, approver, and evidence recorded. Rubber-stamping is monitored through approval rates and sampling. Gate design is in what is a human approval gate.

How does change management apply to prompts and models?

Prompts, model versions, retrieval sources, and tool configurations that affect financial processes are changes to a financial system. Version them, test each change against evaluation criteria on prior close data, require approval by someone other than the developer, deploy through controlled release with rollback, and log every step. Provider model updates count as changes and trigger re-evaluation. Prompt control is in how to build a prompt management system and model control in ai model risk management.

What evidence do auditors expect?

Control documentation with AI's role; evaluation results showing performance within thresholds by category; change logs with approvals; access reviews showing who can alter AI behavior; per-transaction records linking AI output, human decision, approver, and supporting data; and the ability to reproduce any AI-generated explanation or match from the data as of the close. Evidence assembled after the fact does not satisfy. Trail design is in how to build an ai audit trail.

How does segregation of duties apply?

Those who develop or change prompts and models should not approve outputs in the close; production access to alter AI behavior is restricted and reviewed; approval gates enforce authorized roles for postings; and administrative access to the AI platform is segregated from finance roles. Access reviews cover AI systems alongside the ledger. Access design is in ai access control.

How should AI be included in control testing?

Include AI components in general IT controls: access, change management, and operations; test the AI-supported controls by re-performing samples with the evidence; verify evaluation results and change logs; and test that gates enforced approvals. Internal audit can sample AI decisions against source data the same way it samples manual ones. Forecasting controls follow the same pattern; see ai financial forecasting.

What mistakes create deficiencies?

AI posting entries without human approval; prompts changed in production without review; no evaluation evidence for the matching or explanation logic; explanations that cannot be reproduced; developers with production access to AI behavior; and AI described in control narratives as a tool rather than a control component. Each is identifiable in a walkthrough.

What does compliant practice look like?

A company deploys a close assistant that matches transactions and drafts variance explanations. Control narratives document the match rules, thresholds, and the accountant's approval step; every match and explanation carries evidence links; prompts and models are versioned with approvals and evaluation on prior closes; developers cannot change production behavior without controls-team approval; approval rates are monitored; and internal audit re-performs a sample each quarter. External auditors receive the documentation and evidence on request. Sector context is in the AI controls for financial services whitepaper.

How FISTA Solutions helps with SOX and AI

FISTA Solutions builds finance AI systems with human approval gates, evidence links on every output, versioned and approved prompts and models, segregated access, and audit trails that auditors can re-perform, and helps clients document AI's role in their control narratives. The AI enablement practice leads controls design, AI agents ship with the gates, and forward deployed engineers embed with client finance and controls teams. The record behind the approach is 150+ projects with 99.9% uptime.

To put AI into the close without weakening your control environment, message FISTA on WhatsApp, or read how to build an ai financial close assistant for a system built to these standards.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01When does AI fall under SOX controls?

When it contributes to processes that affect financial reporting: reconciliations, journal entry preparation, accruals and estimates, variance analysis, disclosure drafting, or the systems and data feeding them. The AI becomes part of the control it supports and must be documented, controlled, and tested.

02Can AI make control decisions?

Control decisions such as approving a reconciliation, posting a journal, or accepting an estimate should remain with accountable people. AI prepares, matches, drafts, and attaches evidence; humans decide, and the record shows who decided on what evidence.

03How does change management apply?

Prompts, models, retrieval sources, and tool configurations that affect financial processes are changes to a financial system: versioned, tested against evaluation criteria, approved by someone other than the developer, deployed through controlled release, and logged with evidence of each step.

04What evidence do auditors expect?

Documentation of the AI's role in each control, evaluation results showing it performs within thresholds, change logs, access reviews, per-transaction records linking AI output to human decision and supporting data, and reproducibility of any AI-generated explanation from the data as of the close.

05How does segregation of duties apply?

Those who change prompts, models, or configurations should not be those who approve the outputs in the close; developers should not have production access to alter behavior without review; and approval gates should enforce that AI-proposed entries are approved by authorized roles.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. WeтАЩll map the fastest credible path from intent to verified production.

Start a project